Amazon Key Flaw Could Let Rogue Deliverymen Disable Your Camera (wired.com)
Security researchers claim to have discovered a flaw in Amazon's Key Service, which if exploited, could let a driver re-enter your house after dropping off a delivery. From a report: When Amazon launched its Amazon Key service last month, it also offered a remedy for anyone who might be creeped out that the service gives random strangers unfettered access to your home. That security antidote? An internet-enabled camera called Cloud Cam, designed to sit opposite your door and reassuringly record every Amazon Key delivery. Security researchers have demonstrated that with a simple program run from any computer in Wi-Fi range, that camera can be not only disabled, but frozen. A viewer watching its live or recorded stream sees only a closed door, even as their actual door is opened and someone slips inside. That attack would potentially enable rogue delivery people to stealthily steal from Amazon customers, or otherwise invade their inner sanctum. And while the threat of a camera-hacking courier seems an unlikely way for your house to be burgled, the researchers argue it potentially strips away a key safeguard in Amazon's security system. When WIRED brought the research to Amazon's attention, the company responded that it plans to send out an automatic software update to address the issue later this week.
I'd say 'the bad' is that you never really know if every flaw is patched.
Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
I'd say 'the bad' is that you never really know if every flaw is patched
No, you know the answer. The answer is No, they're not patched.
"First they came for the slanderers and i said nothing."
People already allow housekeepers and babysitters into their homes. How is this different?
You get to interview them first?
If it weren't for deadlines, nothing would be late.
Why not give everyone a key to the Amazon warehouse. I'm sure if Amazon has good enough security and tracking, it's users can be trusted.
Amazon wants me to trust them, why doesn't Amazon trust me?
Why can't Amazon ship me stuff while awaiting payment, why don't they take cheques? promissory notes? trades?